What's happening in security
Breaches, credential dumps, actively exploited bugs and AI incidents — pulled from 3,037 items across public feeds, Have I Been Pwned and CISA KEV.
Biggest this week
- Cisco alerts customers to second actively exploited zero-day in as many days — CyberScoop, 1d ago
- Unauthenticated attackers are bypassing Cisco ISE’s management interface (CVE-2026-76460) — Help Net Security, 2d ago
- Google fixes actively exploited Android zero-day on Pixel devices — BleepingComputer, 3d ago
- Cisco warns customers of actively exploited zero-day in email gateways — CyberScoop, 4d ago
- Cisco patches actively exploited email gateway zero-day (CVE-2026-76461) — Help Net Security, 4d ago
-
Snowflake GitHub Actions Flaw Lets Crafted Issues Trigger Command Injection
Cybersecurity researchers at Wiz have disclosed a new GitHub Actions workflow injection vulnerability in Snowflake's public snowflakedb/snowflake-connector-net repository that it said could be exploited through a crafted GitHub is…
-
Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads
A critical security flaw has been disclosed in Forminator Forms, a WordPress plugin with more than 600,000 active installations, that could be exploited to achieve arbitrary code execution on susceptible sites. The vulnerability, …
-
Works start on Datagrid’s Southland AI data centre campus
Southland-based data centre firm Datagrid New Zealand has announced that horizontal works have started on its AI data centre campus in Makarewa, north of Invercargill. The company selected HEB Construction to undertake the works f…
-
Cavern C2 Uses DNS and Google Apps Script to Blend Into Legitimate Traffic
Cybersecurity researchers have traced the continued evolution of the Cavern (aka Cav3rn) command-and-control (C2) framework used by Iranian nation-state hackers in attacks targeting entities in Israel. Russian cybersecurity compan…
-
There are a lot of interesting tidbits, not to mention a lot of shade thrown, in this story about how the Fren…
There are a lot of interesting tidbits, not to mention a lot of shade thrown, in this story about how the French government hacked the EncroChat cryptophone network. https://www. computerweekly.com/news/366649 396/Revealed-Cyber-s…
-
SafePal latest crypto hardware wallet maker affected by breach, with nearly 40,000 impacted
The crypto hardware wallet company SafePal confirmed a data breach on Sunday, telling users that nearly 40,000 customers had information stolen during a recent security incident.
-
Irregular faces criticism over ‘spin’ in AI hacking postmortem
The company at the center of a series of incidents in which AI models compromised real-world computer systems during security evaluations is facing criticism after the release of a report that security experts say leaves key quest…
-
Poland probes MyDr healthcare software breach potentially affecting 19 million people
MyDr, a privately-owned Polish company that supplies software to doctors, clinics and other healthcare providers, said on Friday that it had identified and removed the cause of the incident and introduced additional security measu…
-
How AI Builders Will Get Hacked
How AI Builders Will Get Hacked/images/how-ai-builders-get-hacked.webp/images/how-ai-builders-get-hacked.webp If you are building stuff with AI I have a critical security recommendation for you. Create a continuously-running secur…
-
Linux Botnet Evooo1Bot Expands Mirai Capabilities Well Beyond DDoS
The botnet adds exploitation modules, credential theft, and reverse SOCKS relays to turn compromised devices into persistent attacker infrastructure.
-
Critical flaw in SAP Commerce Cloud faces initial exploitation attempts
The vulnerability has a maximum severity score of 10, indicating serious potential impact and relative ease to exploit by an attacker.
-
We Tracked a Shipment of Rare Books. It Ended at an Amazon AI Training Facility
We Tracked a Shipment of Rare Books. It Ended at an Amazon AI Training Facility Excellent piece of reporting from 404 Media. For a while now there have been stories of book dealers receiving orders for large volumes of books from …
-
Major genetic-testing firm says hack compromised sensitive patient data
The June breach, which also exposed employees information, underscored the supply-chain risks facing the healthcare sector.
-
Microsoft confirms GitHub is down worldwide
GitHub is down for some users as a widespread outage is causing errors across the website, API, Actions, Pull Requests, and several other services. [...]
-
France’s tax authority admits hackers made off with data on 678,000 individuals
France s tax authority has disclosed a data breach after an attacker accessed the General Directorate of Public Finances (DGFiP) systems, saying the intrusion exposed data on 678,000 individuals and professionals. The incident cam…
-
An “invisible” car? Researcher uses machine learning to hide vehicles from Flock cameras
A cybersecurity expert has demonstrated how computer-generated patterns can successfully prevent surveillance cameras from detecting vehicles - such as the controversial AI-powered Flock licence plate readers that are becoming inc…
-
Certighost and the Privilege Hiding in Your Certificate Authority
CVE-2026-54121 lets a standard domain user turn your Enterprise CA into a Domain Controller. The patch is the easy part. The lesson is standing privilege, implicit trust, and treating PKI as the Tier 0 identity infrastructure it h…
-
680,000 Impacted by French Tax Authority Data Breach
Hackers used compromised credentials to access enterprise and personal tax-related data. The post 680,000 Impacted by French Tax Authority Data Breach appeared first on SecurityWeek .
-
Fortinet expands AI security portfolio with Virtue AI acquisition
Fortinet has acquired Virtue AI, strengthening its broader Security for AI strategy and its vision for securing the agentic enterprise. The acquisition builds on Fortinet’s existing AI security portfolio, which includes the FortiG…
-
17th August – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 17th August, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Colombia’s Ministry of Justice has experienced a ransomware attack that affected …
-
⚡ Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and More
The expensive attacks are not always the clever ones. This week had plenty of proof. Exposed services got hit, old bugs found fresh use, browser sessions became attack paths, and supply-chain problems kept spreading farther than t…
-
Cybercrime Magazine Announces Platinum Media Program for Cybersecurity Companies
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Aug. 17, 2026 – Read the Press Release Cybersecurity Ventures launched a Platinum Media Program for VC funded startups, emerging players, and t…
-
Windows Server 2022 reaches end of mainstream support in 60 days
Microsoft has reminded IT administrators that Windows Server 2022 is rapidly approaching its mainstream end date of October 2026, when it will switch to extended support. [...]
-
Ukraine says cyberattack hit Russian e-commerce giant Wildberries amid drone strikes
Ukraine’s military intelligence claimed it disrupted the operations of Russia’s largest online marketplace, Wildberries, in a cyberattack intended to amplify the impact of drone strikes on the company’s infrastructure.
-
Attackers exploit patched macOS Screen Sharing flaw to deploy cryptominer
A recently patched security flaw in Apple macOS is being actively exploited by hackers to bypass authentication, gain root access, and install a cryptominer, the Netherlands’ National Cyber Security Centre (NCSC) warns. The vulner…
-
Irregular Details How a Naming Error Let AI Models Attack a Real Company
The AI security testing firm has shared information on a recently disclosed incident involving Anthropic AI models. The post Irregular Details How a Naming Error Let AI Models Attack a Real Company appeared first on SecurityWeek .
-
How MCP Servers Can Expose Enterprise Secrets
MCP servers can expose enterprise secrets through plaintext configuration files, over-permissioned access and prompt injection, often before security teams even know the server is running. As more organizations adopt AI agents int…
-
Operation ASTERIX: Anatomy of a Crypto Fraud Pipeline
Operation ASTERIX overview Rapid7 researchers identified an exposed web directory on infrastructure used to support a cryptocurrency fraud operation. The server contained raw phone-number datasets, account-validation tools, enrich…
-
Philips and GE investigating Clop ransomware data theft claims
Tech giants General Electric (GE) and Philips have also confirmed they're investigating claims that the Clop ransomware gang breached their systems and stole data. [...]
-
Hacking Public Wi-Fi DNS to Steal Credentials
Criminals are hacking into public Wi-Fi devices at hotels, conference centers, and so on around the world and changing their DNS settings. The goal is to redirect users to fake login pages and steal their credentials.
-
Fix Execution, Not the SOP
A flood of documents pours into a funnel that drips onto a tiny model a man is polishing, while real unbuilt work waits through an open door/images/fix-execution-not-the-sop.webp/images/fix-execution-not-the-sop.webp AI is multipl…
-
Conflicting Test Goals Pushed Claude Agents to Deploy Self-Replicating Malware
Anthropic has been conducting tests to identify issues in how AI agents interact with each other. The post Conflicting Test Goals Pushed Claude Agents to Deploy Self-Replicating Malware appeared first on SecurityWeek .
-
In today's episode of Breach Please, me and @ Secitup talk about whether CTI analysts can use changes in dwell…
In today's episode of Breach Please, me and @ Secitup talk about whether CTI analysts can use changes in dwell times, cyber targeting, etc. as a leading indicator of impending geopolitical events. We generally think there's to muc…
-
Unisoc VoLTE Video Call Exploit Chain Can Give Attackers Full Android Kernel Access
Security researchers at SSD Secure Disclosure have published a two-stage exploit chain that achieves full Android kernel access on devices running Unisoc modem firmware through a VoLTE video call, with no fix from the chipset make…
-
SafePal breach affects 39,798 customers, data allegedly for sale
Cryptocurrency wallet maker SafePal disclosed a data breach that exposed order information for 39,798 customers, including names, email addresses, shipping addresses, phone numbers and purchase details. The company traced the expo…
-
French tax authority data breach affects 678,000 individuals
The French Ministry of the Economy and Finance has disclosed a data breach after an attacker accessed the General Directorate of Public Finances (DGFiP) systems and stole data belonging to 678,000 individuals. [...]
-
40,000 Impacted by SafePal Data Breach
Hackers exploited a vulnerability in the order-tracking function of a plugin to access SafePal customer information. The post 40,000 Impacted by SafePal Data Breach appeared first on SecurityWeek .
-
Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxies
Cybersecurity researchers have flagged a previously undocumented Linux botnet family dubbed Evooo1Bot that derives its core functionality from the Mirai botnet source code and is equipped to turn internet-facing devices into SOCKS…
-
Microsoft working on Defender patch for ShieldBreak zero-day
Microsoft is working on a security patch for the "ShieldBreak" zero-day vulnerability disclosed last week by security researcher "Nightmare Eclipse" and now tracked as CVE-2026-69414. [...]
-
Why more security data has blurred companies’ view of risk
More security data can create blind spots. Here s how to regain visibility.
-
Recent macOS Screen Sharing Vulnerability Exploited in Attacks
Threat actors gained root access to the vulnerable systems and deployed a Monero miner. The post Recent macOS Screen Sharing Vulnerability Exploited in Attacks appeared first on SecurityWeek .
-
Critical SAP Commerce Cloud Vulnerability Exploited 3 Days After Disclosure
The vulnerability tracked as CVE-2026-58231 can be exploited to execute arbitrary code and compromise internal components. The post Critical SAP Commerce Cloud Vulnerability Exploited 3 Days After Disclosure appeared first on Secu…
-
Police bust cybercrime ring accused of stealing €30 million in four-day spree
German and Brazilian police dismantled an international bank fraud ring blamed for a €30 million cyberattack on a German financial institution, arresting four people in Brazil and pursuing three more suspects in Spain and Bulgaria…
-
Africa’s Cybersecurity Challenge Is Bigger Than Access to Technology
Gopan Sivasankaran is Rapid7's Regional Director, Middle East & Africa. Across Egypt, Nigeria, South Africa, and Kenya, organizations are expanding their use of cloud infrastructure, artificial intelligence, digital services, and …
-
Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived Ransomware
Cybersecurity researchers have attributed the exploitation of a newly patched security flaw in Broadcom VMware vCenter to a suspected China-nexus advanced persistent threat (APT). The attacks involve the exploitation of CVE-2026-5…
-
Fortune 500 Companies Hit in Azure Data Theft Campaign
A threat actor is claiming the exfiltration of millions of records from McDonald’s, TCS, Vodafone, and other large organizations. The post Fortune 500 Companies Hit in Azure Data Theft Campaign appeared first on SecurityWeek .
-
Windows 11’s strongest security defenses can be bypassed without a screwdriver
Researchers from the University of Birmingham and Durham University have found a way to knock down some of the toughest protections in Windows 11 without physically opening or modifying the target machine. The attack assumes the a…
-
Hazmat: Open-source containment for AI agents
Hazmat is an open-source tool that runs AI coding agents inside a separate account on your own machine. It wraps the harnesses people use: Claude Code, Codex, OpenCode, Cursor Agent, and several more, plus any script you write you…
-
Product showcase: ScamNet looks for warning signs in suspicious calls and shady links
ScamNet: Anti-Scam Suite is a consumer security app from Synaptrex Technologies that helps users detect and block scams involving phone calls, text messages, websites, and other suspicious content. The app is available for iPhone,…
-
Inside EDGE 2026 Day Two: AI, M&A and the Future Channel
AI dominated the conversation at EDGE 2026 Day two, but it wasn’t the only topic keeping channel leaders talking. From the cybersecurity arms race and the growing skills shortage to marketplace disruption, M A strategy and the fut…
Last fetch · 0 new